North Korea's employment scams work in both directions. As well as planting fake IT workers inside Western companies, regime-backed operators are now posing as recruiters, and the latest international advisory says the scheme has infected more than 30,000 devices and siphoned off over $10 million.
.jpg?width=1280)
Photo: Carl Lender, CC BY 2.0, via Wikimedia Commons
What Happened
How did the WaterPlum attackers infect devices?
Victims were sent files presented as coding assignments or recruitment tests during a fake interview. Opening those files installed remote access trojans and information stealers, giving attackers persistent access to the computer.
What is the scale of the North Korean fake IT worker problem?
Researchers estimate roughly 100,000 North Korean IT workers are employed or seeking work worldwide, and the scheme is thought to net the regime upwards of $500 million a year.
How can I avoid a fake recruiter scam?
Refuse to download files from unsolicited recruiters, run any coding test in a sandbox, keep your system patched, and treat any request to remote into your machine or share wallet keys as a red flag.
Which countries issued the WaterPlum advisory?
Agencies from Australia, Germany, Japan, and the United States issued the joint advisory, published through the US Internet Crime Complaint Center.
On Thursday, agencies from Australia, Germany, Japan, and the United States issued a joint advisory on an ongoing North Korean campaign tracked as WaterPlum. According to the report, attackers posing as recruiters have infected more than 30,000 devices through fake job interviews and compromised more than 7,000 cryptocurrency wallets, with thefts attributed to the scheme reaching at least $10.71 million.
The target list is specific. WaterPlum operators pursue web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicant's computer and installs malware.
Once inside, the attackers deploy remote access trojans (RATs) and information stealers. That gives them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machine later becomes a route into a corporate network when the jobseeker secures legitimate employment.
The advisory, published through the US Internet Crime Complaint Center, spells out the goals in blunt terms. Stolen identity documents let North Korean IT workers impersonate victims and generate foreign currency. Stolen credentials can be used to drain crypto assets, personal data, and trade secrets from an employer, a client, or a contractor. The actors can also use stolen sensitive information for extortion.
The advisory stresses that the operation is still running and expanding. Because the recruiters recycle contact profiles and infrastructure, agencies expect the same tactics to keep surfacing under different names. For organizations that already rely on remote contractors, the practical takeaway is that a hiring decision can now carry a security consequence: bring on the wrong candidate and you may bring on their backdoor.
The pattern here mirrors what small scientific and technical organizations face from infrastructure attacks, a risk that grew sharply in 2026 when cyberattacks grounded everything from meteor-tracking nonprofits to utility providers. When a group relies on volunteer labor and lightly staffed IT, a single compromised machine can cascade into a much larger outage or data loss, exactly as the WaterPlum recruiters intend when they plant a RAT on a jobseeker's device.
Why This Scheme Is Different
The recruiter campaign is the mirror image of a better-known North Korean tactic. For years, the regime has placed its own IT workers in technology roles at Western and allied companies, often with the help of accomplices running laptop farms that make remote workers appear to be based in the country where they were hired.
WaterPlum runs that playbook in reverse. Instead of sending a North Korean operator into your company, it pulls a legitimate applicant into an attacker-controlled machine. The two approaches feed each other. A stolen identity from a WaterPlum infection can be reused to place a fraudulent worker. A compromised device can be used to compromise the company that later hires the applicant.
Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. The sprawling IT worker fraud is thought to net the regime upwards of $500 million a year, much of it surrendered to the state from salaries paid by companies in countries that impose heavy sanctions on North Korea.
What WaterPlum Actually Steals
The advisory itemizes what the backdoored computers hand over:
- Intellectual property and trade secrets from current or future employers.
- Credentials and passwords stored on the device.
- Clipboard contents and keystrokes.
- Cryptocurrency wallet data and private keys.
- Identity documents that can support further impersonation.
That last category is the multiplier. A stolen passport or driver's license does not just expose one victim. It becomes the foundation for the fake-IT-worker pipeline, letting a regime operator pose as a real person during interviews with legitimate companies. Every device infected is potentially both a theft and a source of identities for the larger operation.
The Warning Signs Employers Miss
Because the scheme depends on victims opening files, the most important defenses are on the applicant side. But the advisory also flags signs that help employers spot a fraudulent North Korean candidate, whether from the recruiter variant or the worker variant:
- Resumes that claim prestigious educational backgrounds and extensive experience that do not survive scrutiny.
- Repeated refusals to meet in person.
- Suspicious interruptions to video feeds, or voices in the background.
- Requests for payment in cryptocurrency.
- Use of AI face-swapping software that produces visual artifacts during calls, prompting the applicant to disable the camera shortly after the interview begins.
A Pattern, Not an Anomaly
WaterPlum is the latest chapter in a documented pattern of North Korean cyber operations that blend employment fraud with financial theft. The same RAT techniques resurfaced in North Korean IT worker scams in 2025, and the underlying fake-worker economy has been running for years. The scale is industrial:
| Metric | Value |
|---|---|
| Devices infected by WaterPlum | 30,000+ |
| Cryptocurrency wallets compromised | 7,000+ |
| Theft attributed to WaterPlum | $10.71 million |
| North Korean IT workers worldwide | ~100,000 |
| Estimated annual regime revenue | $500 million+ |
The throughline is not sophistication. It is scale and patience. The regime has built a pipeline that monetizes identity theft, credential theft, and employment fraud at the same time. WaterPlum is the recruitment front of that pipeline, and the advisory makes clear the front is being expanded, not dismantled.
What to Do Now
If you are a jobseeker in web development, engineering, or crypto and Web3:
- Treat unsolicited recruiter outreach that immediately demands you download a file with suspicion.
- Run any downloaded coding test in a sandboxed, isolated environment rather than on your main machine.
- Keep your operating system and antivirus current, and enable endpoint detection where possible.
- Never let a "recruiter" remote into your computer, and never paste wallet private keys into a session.
Sources & Verifications
- The Register (Connor Jones, September 18, 2026): WaterPlum infected 30,000 devices, compromised 7,000 crypto wallets, $10.71 million attributed, four-nation advisory, warning signs. https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
- IC3 Internet Crime Complaint Center (September 18, 2026): joint advisory on WaterPlum recruitment campaign; goals and theft categories. https://www.ic3.gov/CSA/2026/260918.pdf
- The Register (September 25, 2025): Lazarus RAT code resurfacing in North Korean IT worker scams. https://www.theregister.com/security/2025/09/25/lazarus-rat-code-resurfaces-in-north-korean-it-worker-scams/1162142
- The Register (March 18, 2026): estimate of 100,000 fake IT workers netting $500 million a year for North Korea. https://www.theregister.com/security/2026/03/18/north-koreans-100k-fake-it-workers-net-500m-a-year-for-kim/5224468
Post a Comment